hardMultiple ChoiceObjective-mapped
220-1201 Practice Question: A technician is tasked with securing a…
A technician is tasked with securing a workstation that will be used in a public kiosk. The requirement is that the system must only boot from the internal SSD and must prevent booting from USB drives or optical media. Which UEFI security feature should be configured?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Disable all external boot devices in the UEFI boot order and set a supervisor password.
To prevent unauthorized booting from external media, the technician must set a boot order that prioritizes the internal SSD and disable other boot devices. Additionally, setting a UEFI administrator password prevents unauthorized users from changing these settings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Secure Boot and set a UEFI administrator password.
Why it's wrong here
Enabling Secure Boot ensures that only digitally signed operating system boot loaders and drivers are allowed to execute, preventing malicious software from hijacking the boot process. However, Secure Boot does not inherently remove or disable external boot devices from the UEFI boot order. If a USB drive or other external media is still listed as a bootable device, an attacker could potentially boot from it, bypassing the installed OS. A UEFI administrator password protects the settings, but it doesn't prevent booting from an enabled external device if the attacker gains physical access and the device is still in the boot order.
- ✓
Disable all external boot devices in the UEFI boot order and set a supervisor password.
Why this is correct
Disabling all external boot devices, such as USB drives, optical drives, or network boot options, directly prevents the workstation from initiating a boot sequence from any unauthorized media. This ensures the system will only attempt to boot from the internal hard drive. Setting a supervisor password then secures the UEFI/BIOS settings, making it impossible for an unauthorized user to re-enable external boot devices or alter the boot order without the correct credentials, thus maintaining the security posture and preventing unauthorized system access.
- ✗
Set the boot mode to Legacy BIOS and disable USB support.
Why it's wrong here
Switching the boot mode to Legacy BIOS does not inherently prevent booting from external devices; many older systems still support USB booting in this mode, depending on the specific BIOS configuration. Furthermore, completely disabling USB support within the BIOS would render essential peripherals like keyboards and mice non-functional, making the workstation unusable for legitimate purposes. This approach is overly restrictive and does not achieve the specific goal of preventing unauthorized boot attempts while maintaining system functionality.
- ✗
Enable the TPM and set a power-on password.
Why it's wrong here
A Trusted Platform Module (TPM) is primarily designed for cryptographic functions, such as securely storing encryption keys and performing platform integrity checks (attestation), not for controlling the boot order or preventing external device booting. While a power-on password prevents unauthorized users from booting the system at all, it does not specifically prevent an authorized user (or an attacker who bypasses the password) from booting from an external device if it remains enabled in the boot order. The TPM and power-on password do not address the core vulnerability of booting from unauthorized media.
Go deeper
Related to this question
Learn chapter
Storage Devices: HDD, SSD, NVMe
Key term
Unified Extensible Firmware Interface
UEFI is the modern replacement for BIOS that controls how a computer starts up and loads the operating system.
Key term
Universal Serial Bus
A Universal Serial Bus (USB) is a standard interface that allows you to connect devices like keyboards, mice, storage drives, and printers to a computer for data transfer and power delivery.
About these practice questions
This 220-1201 question is part of Courseiva's 972-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1201 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1201 exam.